Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tmontg1 Form Generator for WordPress form-generator-powered-by-jotform allows Stored XSS.This issue affects Form Generator for WordPress: from n/a through <= 1.52.
Published: 2025-09-22
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from improper neutralization of user-supplied input during web page generation in the Form Generator for WordPress plugin. The flaw permits an attacker to embed JavaScript that is stored in the form data and subsequently executed whenever the form is displayed to a visitor. Such stored cross‑site scripting can lead to session hijacking, credential theft, or defacement of the site. The weakness corresponds to CWE‑79, reflecting inadequate input validation and output encoding.

Affected Systems

Site administrators using the Form Generator for WordPress plugin by tmontg1 should be aware that all versions from the first release through version 1.52 are affected. The problem exists in any deployment where the plugin is installed and not patched to a newer release beyond the stated limit.

Risk and Exploitability

The CVSS score of 5.9 indicates a moderate impact. The EPSS score of less than 1% suggests a low probability of exploitation in the current landscape, and the vulnerability is not listed in CISA’s KEV catalog. However, combined with the fact that the flaw allows persistent script injection, the potential damage is significant if an attacker were to target a site. The likely attack vector is through the plugin’s form input fields, where malicious payloads can be stored and later served to other users. Because the vulnerability is stored, any user who views the affected form will be exposed to the injected code.

Generated by OpenCVE AI on April 30, 2026 at 01:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Form Generator for WordPress plugin to the latest version that resolves the cross‑site scripting flaw.
  • If immediate update is not possible, temporarily remove the plugin or restrict access to the affected forms.
  • Use an application security layer such as a web application firewall or a content security policy that blocks inline JavaScript execution.

Generated by OpenCVE AI on April 30, 2026 at 01:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-30535 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tmontg1 Form Generator for WordPress allows Stored XSS. This issue affects Form Generator for WordPress: from n/a through 1.5.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tmontg1 Form Generator for WordPress allows Stored XSS. This issue affects Form Generator for WordPress: from n/a through 1.5.2. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tmontg1 Form Generator for WordPress form-generator-powered-by-jotform allows Stored XSS.This issue affects Form Generator for WordPress: from n/a through <= 1.52.
Title WordPress Form Generator for WordPress Plugin <= 1.5.2 - Cross Site Scripting (XSS) Vulnerability WordPress Form Generator for WordPress Plugin <= 1.52 - Cross Site Scripting (XSS) Vulnerability
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 24 Sep 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 23 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Tmontg1
Tmontg1 form Generator
Wordpress
Wordpress wordpress
Vendors & Products Tmontg1
Tmontg1 form Generator
Wordpress
Wordpress wordpress

Mon, 22 Sep 2025 18:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tmontg1 Form Generator for WordPress allows Stored XSS. This issue affects Form Generator for WordPress: from n/a through 1.5.2.
Title WordPress Form Generator for WordPress Plugin <= 1.5.2 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Tmontg1 Form Generator
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T00:58:54.557Z

Reserved: 2025-09-03T09:03:35.443Z

Link: CVE-2025-58665

cve-icon Vulnrichment

Updated: 2025-09-23T16:02:39.334Z

cve-icon NVD

Status : Deferred

Published: 2025-09-22T19:16:17.280

Modified: 2026-04-23T15:33:33.327

Link: CVE-2025-58665

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T01:45:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')